Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sure hope everyone got that css history hack fix.


Not sure what you mean by ‘got the fix’ — wouldn’t the fix be completely disabling browser history?


There was a hack to see what pages someone visited. I see that they actually link to a page about that. The problem with that approach would seem to be that it is a cross-domain vulnerability so other domains could detect the history thus ever-cookie data.

Not sure if they have some other mechanism for preventing this problem. I actually thought this problem had been resolved in some manner in many browsers but that doesn't appear to be the case.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: